Psynth Is ISO/IEC 27001 Certified. Here Is What That Means for Psychologists

Author
Reviewed By

Psynth Is ISO/IEC 27001 Certified. Here Is What That Means for Psychologists

‍

Psynth has earned ISO/IEC 27001:2022 certification for the information security management system behind its psychological assessment platform. The certificate adds independent evidence to a security program built around highly sensitive clinical data.

‍

Psychologists should not need to become security engineers to decide whether software is fit to handle patient information. But they should be able to ask for evidence.

‍

Psynth is now certified to ISO/IEC 27001:2022, the internationally recognized standard for information security management systems. Glocert International Certifications (UK) Limited issued the certificate on September 30, 2026 after an independent audit.

‍

The certification covers the development, delivery, and support of Psynth’s AI-assisted psychological assessment platform. Its scope includes the web application, supporting cloud environments, and AI model integrations used to process patient data, clinical documents, test results, and assessment reports.

‍

For psychologists, the practical meaning is simple: Psynth’s approach to information security has been examined against a recognized international standard. It is evidence of a managed security program, not just a promise on a website.

‍

ISO/IEC 27001

‍

What is ISO/IEC 27001?

‍

ISO/IEC 27001 sets requirements for an information security management system, often shortened to ISMS.

‍

An ISMS is the operating system for how a company manages information risk. It covers more than encryption or passwords. It asks whether the organization has a repeatable way to:

‍

  • identify security risks;
  • assign responsibility;
  • control access;
  • train staff;
  • manage vendors;
  • prepare for incidents;
  • test safeguards; and
  • improve when systems, threats, or business needs change.

‍

Think of a well-run psychology practice. Locking the records room matters, but it is not the whole privacy program. The practice also needs rules for who receives a key, what happens when an employee leaves, how records are backed up, how an incident is handled, and who checks that the rules are followed.

‍

ISO/IEC 27001 applies that same discipline across an entire company.

‍

Why this matters for psychological assessment

‍

Psychological assessment records can contain cognitive profiles, trauma histories, behavioral observations, diagnostic impressions, family information, educational records, medical documents, and legal evidence.

‍

The sensitivity does not disappear when software makes the work faster. If anything, an AI-assisted workflow creates more questions:

‍

  • Who can access the information?
  • Where is it stored?
  • Which systems process it?
  • How are vendors reviewed?
  • What happens if a control fails?
  • Is anyone independently checking the answers?

‍

ISO/IEC 27001 does not answer every product-specific question by itself. It does show that the organization has established and audited a system for managing those questions and the risks behind them.

‍

That distinction matters to individual clinicians, and it matters even more to multi-clinician practices and enterprises. Security review is often a prerequisite before an organization can evaluate workflow, clinical fit, or price.

‍

What was actually certified?

‍

Psynth’s certificate applies to the information security management system supporting the development, delivery, and support of its AI-assisted psychological assessment platform.

‍

That scope includes:

‍

  • the Psynth web application;
  • supporting cloud environments;
  • AI model integrations; and
  • the workflows used to process patient data, clinical documents, test results, and assessment reports.

‍

The certificate number is 26ISMS-1263. It is valid from September 30, 2026 through September 29, 2029, subject to ongoing surveillance audits.

‍

The surveillance requirement is important. ISO/IEC 27001 is not meant to be a trophy placed on a shelf. The management system must continue operating as the company, product, and threat landscape change.

‍

Psynth Is ISO/IEC 27001 Certified.

ISO/IEC 27001, SOC 2, and privacy laws are not the same thing

‍

Security language becomes confusing when every framework is described as a “certification.” The distinctions are worth keeping clear.

‍

  • ISO/IEC 27001:2022 certification means an independent certification body audited Psynth’s information security management system against the international standard.
  • SOC 2 Type II is an attestation report. Psynth received an unmodified opinion with no exceptions after its controls were tested over an observation period.
  • HIPAA, GDPR, and PIPEDA are laws or regulatory regimes, not ISO-style certifications. Psynth operates as a HIPAA Business Associate to clinician customers and as a data processor under GDPR and PIPEDA, supported by documented compliance programs.

‍

These forms of assurance complement one another. ISO/IEC 27001 examines the management system for information security. SOC 2 Type II evaluates whether described controls operated effectively over time. HIPAA, GDPR, and PIPEDA impose legal and contractual responsibilities in their respective contexts.

‍

None should be collapsed into a single badge.

‍

Security continued beyond the audit

‍

Certification describes a verified management system. Architecture determines how that system is put into practice.

‍

Since the ISO audit began, Psynth has brought its core AI extraction and report-generation operations inside its own Google Cloud environment. This gives Psynth more direct control over access, monitoring, configuration, and regional deployment than a workflow that simply sends sensitive case material to a collection of external AI APIs.

‍

Google Cloud remains an infrastructure provider. Self-hosting does not mean operating without vendors, and it does not eliminate risk. It means Psynth controls the environment in which the core AI workflow operates and can apply its security program more directly.

‍

Patient records, session data, and finalized reports are stored at rest in the customer’s region: the United States, the European Union, or Canada. Processing locations and any required transfers are governed separately by Psynth’s current terms and data-transfer agreements. Buyers should examine both storage and processing, because they are related but different questions.

‍

What certification does not mean

‍

ISO/IEC 27001 certification is meaningful evidence. It is not a promise that a security incident can never happen.

‍

It does not mean:

‍

  • every cyberattack will be prevented;
  • every employee or vendor will always make the right decision;
  • every clinical report is accurate;
  • every use of the platform is automatically lawful; or
  • a psychology practice can stop managing its own privacy and security duties.

‍

A useful analogy is board certification in professional practice. A credential gives you important evidence about training and standards. It does not guarantee that no error will ever occur. You still consider scope, current practice, judgment, and the needs of the specific case.

‍

The same is true here. ISO/IEC 27001 should strengthen trust because it replaces unsupported assurances with independent review. It should not replace due diligence.

‍

Glocert International

‍

What psychologists and organizations should ask any AI vendor

‍

A certificate is a strong starting point. The next questions should connect it to the actual product:

‍

  1. What is included in the certificate’s scope? A certificate may cover an entire platform or only a narrow part of the business.
  2. Can we review the certificate and supporting evidence? Security claims should be verifiable.
  3. Where is patient information stored and processed? Ask about both, not just where data rests.
  4. Which subprocessors can handle sensitive data? Ask what each provider does and which agreements govern the relationship.
  5. How are access, incidents, deletion, and vendor changes managed? The day-to-day procedures matter as much as the headline control.
  6. What remains our responsibility? No software vendor can assume the clinician’s legal, ethical, and professional obligations.

‍

Psynth publishes security controls, audit materials, policies, and its subprocessor list through the Psynth Trust Center. Organizations can use that evidence during procurement, risk review, or vendor reassessment.

‍

Security is an obligation to patients

‍

Psynth began its five-framework security and privacy program in November 2025. ISO/IEC 27001 certification completes that program alongside SOC 2 Type II and Psynth’s HIPAA, GDPR, and PIPEDA compliance work.

‍

The purpose is not to collect logos. Psychological assessment data deserves disciplined protection because of what it can reveal about a person’s health, history, relationships, education, and future.

‍

That obligation applies whether Psynth is used by a solo practitioner, a multi-clinician practice, or a large enterprise. Independent audits help make the obligation visible. The daily work of access control, risk review, incident preparation, vendor management, and continuous improvement is what keeps it real.

‍

Review Psynth’s security evidence in the Trust Center or request a demonstration for your organization.

Frequently Asked Questions

What is ISO/IEC 27001:2022?

ISO/IEC 27001:2022 is an international standard for information security management systems. It requires an organization to identify information risks, implement appropriate controls, assign responsibility, monitor performance, and continually improve its security program.

Is Psynth ISO/IEC 27001 certified?

Yes. Psynth was certified to ISO/IEC 27001:2022 on September 30, 2026 by Glocert International Certifications (UK) Limited after an independent audit. The certificate number is 26ISMS-1263 and it is valid through September 29, 2029, subject to surveillance audits.

What parts of Psynth are covered by the certification?

The scope covers the development, delivery, and support of Psynth’s AI-assisted psychological assessment platform, including the web application, supporting cloud environments, and AI model integrations used with patient data, clinical documents, test results, and assessment reports.

Does ISO/IEC 27001 certification mean a breach is impossible?

No. No certification can make a security incident impossible. ISO/IEC 27001 provides independent evidence that Psynth has a structured, audited system for identifying and managing information security risks.

How is ISO/IEC 27001 different from SOC 2 Type II?

ISO/IEC 27001 certifies an information security management system against an international standard. SOC 2 Type II is an attestation report that evaluates whether described controls operated effectively over a period of time. Psynth has both.

Does ISO/IEC 27001 certify HIPAA, GDPR, or PIPEDA compliance?

No. HIPAA, GDPR, and PIPEDA are separate legal and regulatory regimes. Psynth’s ISO/IEC 27001 certification complements, but does not replace, its HIPAA, GDPR, and PIPEDA compliance programs.

Does Psynth self-host its AI operations?

Psynth runs its core data-extraction and report-generation operations inside its own Google Cloud environment. This gives Psynth more direct control over the core AI workflow, while Google Cloud and other disclosed providers remain part of the broader service environment.

Where can I review Psynth’s security evidence?

Psynth publishes security controls, audit materials, policies, and its subprocessor list through the Psynth Trust Center. Access to some reports may require a request or confidentiality agreement.

See Psynth work in real time

We’ll demo an end-to-end report writing process and answer any questions along the way. (Yes, it’s so quick, we can get through it all during a single call.)
Book a Demo ->